No zero-day here. Someone got hold of a supplier’s legitimate lookup access to a national identity register and ran it hard for about ten days. That’s a pattern every enterprise with a partner API should recognize.
What the ministry said. Per the Oct 5 release, the unauthorized access covered names, addresses and CPR numbers, among other fields, for about 8.8 million registered people (living, emigrated, deceased and others). People registered with name and address protection were not included in what was accessed. CPR’s administration stopped the company’s access and is working with specialists and authorities to map what happened. Minister Christina Egelund called it “a deeply serious incident,” briefed parliament’s digitalisation committee, and ordered a full security review of the CPR system. The ministry also warned people never to hand over passwords over the phone or by email, even when the caller already knows their name, address and CPR number.
How it was pulled. Datatilsynet told The Record it was notified Sunday and described the incident as a very large number of automated searches aimed at identifying valid CPR numbers. Egelund told Ritzau the access ran for roughly ten days in September through a smaller Danish company, and that the security measures around that company’s access “have not been good enough.” She said it’s too early to say whether people will need new CPR numbers. TechCrunch puts discovery at Oct 2 and calls it likely the largest breach in Danish history. The company, the attacker and how the credential was obtained are all Undisclosed.
Why it hits enterprises, not just government. CPR numbers are used across Danish banking, healthcare and government services, and they’re meant to last a lifetime, so this data stays useful to fraudsters for years. Any bank, insurer, telco or employer that verifies Danish customers or staff by CPR number plus name and address should treat that check as worthless as of today. Expect a wave of vishing and helpdesk reset attempts where the caller already “knows” all three.
What we’d do this morning. If you run a lookup API that partners query, the lesson is query shape, not perimeter. Baseline each partner’s normal volume and hit rate, and alert when a client starts enumerating, meaning lots of queries, a high miss rate, and sequential or date-of-birth-patterned IDs. Bind each credential to a stated purpose and a hard daily cap, and make sure someone actually reviews those caps. On the consuming side, pull CPR or national ID from any helpdesk or call-center identity check, step up to a possession factor, and brief the service desk today. Nordic security teams should also inventory which of their own vendors hold CPR lookup access on their behalf.
Desk sheet: ministry release Oct 5: ~8.8M registered people; names, addresses, CPR numbers and more; abuse of a Danish company’s lawful CPR search access; noticed evening of Oct 2; occurred in September; protected-address records excluded; access stopped; Datatilsynet notified; full CPR security review ordered. Ritzau via nyheder.dk: about ten days in September; smaller Danish company; minister says controls on that access weren’t good enough. Datatilsynet via The Record: very large number of automated searches to find valid CPR numbers. Company, attacker and initial access: Undisclosed.
